Bitcoin Bridge Exploited: Third Wrapped-Token Hack in Weeks Sees Billions in Fake Coins Minted
A security flaw in the Symbiosis bitcoin bridge allowed an attacker to mint a vast quantity of unbacked synthetic BTC (syBTC), tricking the system into creating tokens with a face value in the billions that were never actually backed by real bitcoin. The attacker managed to sell only a small portion of this fake supply, netting around $336,000 in wrapped bitcoin (WBTC) before the rest of the phony tokens became worthless because no one would buy them.
Symbiosis confirmed the incident occurred at approximately 04:28 UTC on 11 September 2026, and said it has since halted BTC-related routes while other routes remain operational. The team reported recovering around 15 BTC and has offered the attacker a 20% white-hat bounty to return the remaining funds, with the same offer extended to anyone who provides information leading to recovery. As of publication, Symbiosis had not released a technical explanation of how the vulnerability occurred or a final loss estimate.
This is the third similar incident in recent weeks, following comparable exploits against Blockstream's Liquid Network and Nomic's nBTC bridge, both of which involved tricking bitcoin-wrapping projects into printing coins not backed by real reserves. The recurring pattern highlights a systemic weakness in how some cross-chain bitcoin bridges verify and back the tokens they issue.
Key Takeaway: Businesses using or holding wrapped cryptocurrency assets should treat cross-chain bridges as high-risk infrastructure and avoid relying on them for significant value until proven track records and independent audits are in place.